Suspicious
Suspect

eb77d1b6d71d1efefe59ca8f1275867f

PE Executable
MD5: eb77d1b6d71d1efefe59ca8f1275867f
Size: 12.2 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 eb77d1b6d71d1efefe59ca8f1275867f
Sha1 2bf00f24a13a469845f8b2244e8d58dfba02ab31
Sha256 203af48227a87e5a219bb46ea7cd2fe5959d8d90025a026a67487526658095b6
Sha384 73947e7bf1db6ef9c34f6b48b419a5ff6b1b3f8c2e4ab84d2205b4a24572084c484c80923b7ca2376f57ed675d1397a7
Sha512 58acd40cb8ffac7af19f683531f81cd24c7738f58e030a684b4b8d526adee5eaed3f8feeb7267ef6d8d446ce02a79994476263801cfad53ba328bc234f277019
SSDeep 196608:xv3e7VRjRMLM3Edn9RzdQGW1TLR8I+UiYZ2487Vi+/ly2EXqoF2vtENkwpsWRDOY:xv3E+LOEdn3piTLq4GBVi+/lJEq6NkwT
TLSH 16C6338517A5D80ADC856A325E70CF746E781E87A620C20B6FF03E677F39BB16E15207
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NestingBox.Properties.Resources.resources
Sed
[NBF]root.Data
rjSa
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
gssZ.exe
Full Name
gssZ.exe
EntryPoint
System.Void NestingBox.Program::Main()
Scope Name
gssZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gssZ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
321
Main Method
System.Void NestingBox.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NestingBox.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NestingBox.Properties.Resources.resources
Sed
[NBF]root.Data
rjSa
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙